nanog mailing list archives

Re: not rewriting next-hop, pointing default, ...


From: Randy Bush <randy () psg com>
Date: Thu, 11 Sep 97 15:54 PDT

LSR is actually a significant security issue.  So, while I do
understand and am sympathetic to the operational debugging
issues that LSR addresses, I think that requiring a peer to
enable LSR more than 2 hops inside their network from the
outside world is unreasonable.

So, you're comfortable with asking for LSR at the IX and a hop behind?

In a world where SSH were available in cisco routers and/or
IPsec were more widely deployed, I might have different views.

K5 does not give you sufficient warm fuzzies?

randy


Current thread: